Skip to content

Sandbox quick start

You can evaluate the platform end to end without contacting anyone. Everything in the sandbox is for testing: its certificates chain to a sandbox-only root and are never accepted as genuine.

Sign up in the developer console with your work email, verify it, and add an authenticator app. The console will not act until you have a second factor.

In the console, name your organization. You get a sandbox organization, active at once, with the capabilities an integration usually needs, and one application.

Open the application’s credentials, create its OAuth client and request a workload certificate. See Credentials for what happens and how to call the API with them.

A Postman collection of every operation, generated from the contract, is ready to import. Set base_url and access_token, and add your client certificate in Postman’s certificate settings.

Every sandbox organization knows a fixed set of synthetic subscribers, one per outcome: approval, rejection, expiry, compromise, a failing webhook and more. Use one in an ordinary call and the sandbox produces its outcome. There is no header or switch to set, so the code you test is the code you ship. These subscribers exist only in sandbox.

The Scenarios tab lists them, and GET /v1/sandbox-scenarios returns the same list. The identifiers are stable and safe to hard-code. A scenario marked “Coming soon” has its subscriber in place but not yet its outcome.

Under People, invite colleagues by email with a role:

Role May
Administrator Everything, including people and going live
Developer Configure and credential the sandbox; read production
Security administrator Manage and revoke credentials and certificates; read audit
Billing contact See usage and the team

The same people and roles apply in sandbox and production.

Production is reviewed. An administrator submits your organization’s verification; once NCC has verified it and approved the promotion, your production organization appears in the console beside the sandbox, with the same team.

Going live is reviewed once for the organization. Each sandbox application’s page shows its way there: request production access with that application (NCC assesses its integration), follow the review and its readiness checks, and once the organization is live, create the application in production. The production application gets its own credentials and webhooks; nothing secret is copied from the sandbox.